Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected when customers use our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, customers acknowledge that they have read this policy and understand how their personal information is handled.
1. Data Controller and Scope
For the purposes of applicable data protection law, we act as the data controller in relation to the personal data we collect and determine the purposes and means of processing. This policy applies to personal data collected from customers, prospective customers, and users who interact with our services in the area. It covers data collected directly from individuals, data generated through use of the services, and data received from third parties where permitted by law.
2. Personal Data We Collect
We collect only data that is necessary, relevant, and proportionate for the purposes described in this policy. Depending on the nature of the interaction, the categories of data may include:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Account data: login credentials, account preferences, and profile information.
- Transaction data: records relating to purchases, payments, invoices, and service history.
- Technical data: IP address, device identifiers, browser type, operating system, and usage logs.
- Interaction data: information about how customers engage with our services, including support requests and service preferences.
- Marketing data: preferences for receiving promotional communications, where applicable.
We do not intentionally collect special category data unless such processing is required or permitted by law and is necessary for a specific service or legal obligation. Where such data is processed, we apply enhanced safeguards in line with GDPR requirements.
3. How We Use Personal Data
We process personal data for the following purposes:
- to provide, operate, and maintain our services;
- to manage accounts and customer relationships;
- to process transactions and fulfil requests;
- to communicate service updates, notices, and administrative information;
- to improve service performance, functionality, and security;
- to respond to enquiries, complaints, and support requests;
- to comply with legal and regulatory obligations;
- to detect, prevent, and investigate fraud, misuse, or security incidents;
- to send marketing communications where permitted by law and subject to any required consent or opt-out rights.
We ensure that all processing is carried out in a fair, lawful, and transparent manner. We apply the principle of data minimisation and collect or retain only the data that is necessary for the stated purpose.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following lawful bases:
Performance of a Contract
We process personal data where it is necessary to enter into or perform a contract with a customer, including managing accounts, providing services, and processing payments.
Legal Obligation
We process personal data where required to comply with legal obligations, including accounting, tax, consumer protection, fraud prevention, and other regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by the individual’s rights and freedoms. Examples include improving services, maintaining security, and preventing abuse.
Consent
Where required, we rely on consent, particularly for certain marketing activities or optional data uses. When consent is used as a lawful basis, it is freely given, specific, informed, and unambiguous. Individuals may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties that help us operate our services. These parties act as processors under GDPR and are only permitted to process personal data on our documented instructions. They are required to protect data, use it only for agreed purposes, and implement appropriate technical and organisational security measures.
Processors may include providers of:
- IT hosting and infrastructure services;
- payment processing services;
- customer support and communication tools;
- analytics and performance monitoring tools;
- security, fraud detection, and compliance services;
- administrative and document management services.
We may also disclose personal data where necessary to comply with law, respond to lawful requests, protect our rights, or protect the safety of customers, staff, or the public. Where personal data is transferred outside the European Economic Area, we will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent lawful transfer mechanisms.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods vary depending on the category of data and the reason for processing.
In determining retention periods, we consider:
- the nature and sensitivity of the data;
- the risks associated with unauthorised use or disclosure;
- the purposes of processing;
- legal, regulatory, and contractual obligations;
- whether a customer has requested deletion or exercised a relevant right.
When personal data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a manner that prevents unauthorised access or reconstruction. We do not keep data indefinitely without a lawful reason.
7. Security Measures
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Such measures may include access controls, encryption, secure storage, logging, staff confidentiality obligations, and periodic security reviews. While no system can be guaranteed completely secure, we take reasonable steps to reduce risk and maintain an appropriate level of protection.
8. User Rights Under GDPR
Individuals whose data we process have a number of rights under GDPR, subject to legal conditions and exceptions. These rights include:
- Right of access: to obtain confirmation and a copy of personal data we hold.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive data in a structured, commonly used format where applicable.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Right not to be subject to automated decision-making: to challenge certain decisions made solely by automated means, where applicable.
- Right to withdraw consent: where processing is based on consent, individuals may withdraw it at any time.
Requests will be assessed in accordance with applicable law. We may need to verify identity before responding to a request. If a request is manifestly unfounded or excessive, we may refuse it or charge a reasonable fee where permitted by law.
9. Children’s Data
Our services are not intended to be used by children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate lawful basis and, where required, parental or guardian authorisation. If we become aware that data has been collected inappropriately, we will take reasonable steps to delete it promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our processing practices, or operational needs. Any updated version will apply from the date it is published or otherwise communicated. Customers are encouraged to review the policy periodically to remain informed about how their data is handled.
11. General Principles
We are committed to processing personal data in accordance with the core principles of GDPR, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability. These principles guide all decisions about how personal data is collected and used.
In summary, we collect and use personal data only where necessary, rely on a valid lawful basis, protect data with suitable safeguards, and respect the rights of all customers in the area. This policy applies to all customers in the area and is designed to ensure that personal information is handled responsibly, securely, and in compliance with applicable data protection law.
